CVE-2025-3028: Mozilla Firefox

Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.

JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability was fixed in Firefox 137, Firefox ESR 115.22, Firefox ESR 128.9, Thunderbird 137, and Thunderbird 128.9.

Affected products

  • Mozilla Firefox: before 115.22.0 (fixed in 115.22.0); before 137.0 (fixed in 137.0); from 116.0, before 128.9.0 (fixed in 128.9.0)
  • Mozilla Thunderbird: before 128.9.0 (fixed in 128.9.0); from 129.0, up to and including 137.0

Published 2025-04-01. Last modified 2026-10-05.